Evanston Township High School District 202

Evanston Township High School District 202’s live incident page still described ongoing ransomware recovery and limited system access on August 3. Home Access Center, myETHS and district phones remained unavailable, staff devices required review, and records and parking workflows used phased replacement systems and temporary channels. Personal-information access, extortion details and actor attribution remain unresolved.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
Internal or external network connectivity was unavailable or materially impaired.
The organization lost or materially restricted internet connectivity.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.
The disruption created or increased a risk to physical safety, public safety, patient safety, industrial safety, or safe operations.
A primary service, system, platform, or operational capability became entirely unavailable.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.
A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.
A specific application or software platform became unavailable or unusable.
Users were unable to authenticate, sign in, access accounts, or use identity-dependent services.
Staff, customers, patients, students, residents, or other users could not access records or case information normally.
The organization could not create, update, search, file, approve, transmit, or otherwise process records normally.
Instruction, student services, school administration, learning platforms, transportation, or other educational operations were materially affected.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Services continued but with longer processing, response, delivery, or completion times.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub assesses with high confidence that Evanston Township High School District 202 experienced a ransomware attack beginning June 7, 2026. The district’s rolling incident page confirms that the event disrupted district systems, internet services and computer infrastructure. DysruptionHub’s initial report and CBS News Chicago documented the immediate campus, communications and safety effects.
The district has not identified the access vector, ransomware family, compromised accounts, encryption scope or responsible actor. Ransomware is confirmed by the victim, but the technical and attribution picture remains limited.
The attack disrupted network connectivity, internet, phones, staff email and Google accounts, eSchool, Home Access Center, myETHS, door access, public-address functions and other emergency or operational systems. Because systems required for safe operations were unavailable, ETHS closed campus June 8–9 and canceled summer school, sports camps and other activities. Campus reopened June 10, but that did not mark full technology restoration.
In a July 16 school-year preparation statement, Superintendent Marcus Campbell said core servers had been inaccessible for about a month and that teams were rebuilding critical systems and restoring services. The district expected some tools, processes and timelines to function differently, with services returning in phases and temporary workarounds continuing into the school year.
The rolling incident page says Home Access Center and myETHS are no longer available, Home Access Center remains unavailable for grades, district phones remain down and staff access to systems and devices remains restricted during recovery. Student records are moving to Infinite Campus in phases. The incident interrupted transcript-data transfer, although the missing-grade issue was later corrected through Parchment.
The district’s student-parking page documents a delayed lottery, a replacement registration form, temporarily unavailable detailed account information and phone, email and in-person payment alternatives. These effects support records-processing disruption, service delay and alternate-channel use in addition to the previously documented outages and manual workarounds.
Recovery remained active as of August 3. The district’s live incident page continued to say response and restoration were ongoing, campus was operating with limited system functionality, students and families could not access some online resources, and teachers and staff had limited system access. The temporary parking workflow also extended through an August 3 second-round lottery, with permit pickup scheduled for August 6–7. No later full-restoration or all-clear notice was found.
Confidence is high that ransomware caused material educational and safety-related disruption because the district directly confirmed the attack type and affected systems. Data availability was affected because core servers, records portals and some information workflows were inaccessible. Whether personal information was accessed, copied or removed remains unresolved; the district said forensic specialists were still examining that question.
CBS reported that the district had not received a money demand at the time of initial reporting. No later demand, payment, leak-site listing, data publication or actor attribution was found, so extortion details and attribution remain unresolved.
The public record does not identify the access vector, ransomware family, dwell time, persistence, affected endpoints or servers, encryption scope, backup impact, ransom amount, payment status or responsible actor. It also does not establish whether student, employee or other sensitive information was acquired, the full recovery cost, or when every affected system and workflow will be restored.

The district’s live incident page continued to state August 3 that response and recovery were ongoing and campus and staff system access remained limited. Home Access Center and myETHS were unavailable, district phones remained down, staff devices required review, and student records were moving to Infinite Campus in phases.
DysruptionHub reported that ransomware disrupted district systems, internet services, phones, staff email, Google accounts, eSchool and Home Access Center. The district closed campus and canceled summer programs because critical operational and safety systems were unavailable.
CBS News Chicago reported that the district closed campus after ransomware disrupted internet, phones, emergency notification and public-address systems. The district said it had not yet received a money demand and staff scheduled to work were told to stay home or work remotely.
Superintendent Marcus Campbell said the June incident caused widespread disruption and significant technology damage, leaving core servers inaccessible for about a month. Critical systems were being rebuilt, some tools and processes would not function normally for the start of school, and phased restoration and temporary workarounds would continue.
The district’s current parking page said the cyber incident delayed the 2026-27 lottery and required a temporary registration and allocation process. Detailed account information remained unavailable online; alternate payment channels were provided; and the replacement workflow continued through an August 3 second-round lottery and August 6-7 permit pickup.
Signed-in members can report an error, update, or missing source.